The U.S. Federal Trade Commission reached a proposed settlement with data broker Kochava and its subsidiary Collective Data Solutions that would prohibit them from selling, sharing, or disclosing sensitive location data without consumers’ affirmative express consent. The FTC said Kochava sold precise geolocation data tied to hundreds of millions of mobile devices, along with related information such as mobile device IDs, app usage data, and demographic details, in ways that could expose visits to sensitive locations including health care facilities and places of worship.
The proposed order, approved by the FTC in a 2-0 vote and filed in federal court in Idaho, requires Kochava to limit sensitive location data use to consumer-requested services, verify suppliers’ consent practices, notify the FTC about certain improper third-party disclosures, tell consumers who purchased their precise location data, allow consent to be withdrawn, and follow a retention and deletion schedule. The case stems from an FTC lawsuit first filed in 2022, and while the settlement does not impose a fine, it formalizes restrictions that overlap with commitments Kochava had already made in a separate class-action settlement to stop monetizing sensitive location data collected through app SDKs.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
On May 4, 2026, the FTC announced a proposed settlement with Kochava and subsidiary Collective Data Solutions, approved by a 2-0 vote and filed in federal court in Idaho. The order would bar the companies from selling, sharing, or disclosing sensitive location data without consumers' affirmative express consent and impose compliance, transparency, and data-deletion requirements.
In November 2025, Kochava agreed in a class-action settlement to stop sharing or selling sensitive location data and to stop monetizing location data collected through app SDKs.
On 2023-11-06, a judge unsealed the FTC's complaint against Kochava, making public allegations about the company's extensive location-data brokerage practices. The unsealing exposed more detail about the FTC's claims regarding the sale of sensitive geolocation information.
In 2023, an FTC complaint further described Kochava's data practices, alleging the company collected and sold information including mobile device IDs, app usage data, income data, and near-real-time location data as unfair and deceptive conduct.
In August 2022, the FTC sued data broker Kochava, alleging it illegally obtained and sold precise geolocation and related data from hundreds of millions of mobile devices in ways that could reveal visits to sensitive locations such as health facilities and places of worship.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcetherecord.media
Open sourceftc.gov
Open sourcetherecord.media
Open sourcetherecord.media
Open sourceftc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.